CVE-2026-4825: SourceCodester Sales and Inventory System HTTP GET Parameter update_sales.php sql injection
A vulnerability was found in SourceCodester Sales and Inventory System 1.0. This affects an unknown part of the file /updatesales.php of the component HTTP GET Parameter Handler. The manipulation of the argument sid results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4825?
CVE-2026-4825 is classified as a critical vulnerability due to its potential for SQL injection exploitation.
How do I fix CVE-2026-4825?
To fix CVE-2026-4825, sanitize and validate all HTTP GET parameters in the update_sales.php file.
What components are affected by CVE-2026-4825?
CVE-2026-4825 affects the HTTP GET Parameter Handler in the SourceCodester Sales and Inventory System version 1.0.
What type of vulnerability is CVE-2026-4825?
CVE-2026-4825 is an SQL injection vulnerability that allows attackers to manipulate database queries.
Who is the vendor of the affected product for CVE-2026-4825?
The vendor of the affected product for CVE-2026-4825 is SourceCodester.